Bulletin ID
Security updates available for Adobe Experience Manager | APSB18-26
|  | Date Published | Priority | 
|---|---|---|
| APSB18-26 | August 14, 2018 | 2 | 
Summary
Adobe has released security updates for Adobe Experience Manager. These updates resolve one Reflected Cross-site Scripting vulnerability rated Moderate that could result in sensitive information disclosure, one Input Validation Bypass vulnerability rated Moderate which could allow unauthorized information modification and one Cross-site Scripting vulnerability rated Moderate that could result in sensitive information disclosure.
Affected product versions
| Product | Version | Platform | 
|---|---|---|
| Adobe Experience Manager | 6.4 6.3 6.2 6.1 6.0 | All | 
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
| Product | Version | Platform | Priority | Availability | 
|---|---|---|---|---|
| 
 
 
 Adobe Experience Manager | 6.4 | All | 2 | |
| 6.3 | All | 2 | ||
| 6.2 | All | 2 | ||
| 6.1 | All | 2 | ||
| 6.0 | All | 2 | 
Please contact Adobe customer care for assistance with earlier AEM versions.
Vulnerability details
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers | Affected Version | Download Package | 
|---|---|---|---|---|---|
| Reflected Cross-site Scripting | Sensitive Information disclosure | Moderate | CVE-2018-12806 | AEM 6.1 AEM 6.2 | |
| Input Validation Bypass | Unauthorized Information Modification | Moderate | CVE-2018-12807 | AEM 6.3and earlier | |
| 
 
 Cross-site Scripting 
 
 | 
 
 Sensitive Information disclosure 
 
 | 
 
 Moderate 
 
 | 
 
 CVE-2018-5005 
 
 | 
 AEM 6.2 AEM 6.3 AEM6.4 | 
The packages listed in the table above are the minimum fix packs to address the listed vulnerability. For the latest versions, please see the release notes links referenced above.
Acknowledgments
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:
- Nagamarimuthu of Cognizant Technology Solutions - Enterprise Risk & Security Solutions (CVE-2018-12806) 
- Chia Min Jun Lennon (CVE-2018-12807)